Important: This requirement applies to all relevant Salesforce orgs
This security requirement applies to every Salesforce org in which Payments2Us is installed, including your production org and all Sandbox environments.
Within each org, the setting must be reviewed for every Salesforce Site that hosts Payments2Us forms. If you have more than one Payments2Us Site, complete the required steps separately for each site.
If your Payments2Us forms are hosted on a public-facing Salesforce Experience Cloud site and can be accessed without requiring users to log in, please log a support case directly with Payments2Us.
Overview
As part of our ongoing commitment to security, Payments2Us requires customers hosting Payments2Us forms on Salesforce Sites to disable the Lightning Features for Guest Users setting.
This requirement applies to every Salesforce org in which Payments2Us is installed, including production and Sandbox environments.
If your Payments2Us forms are hosted on a public-facing Salesforce Experience Cloud site and are available to users without authentication, please log a support case directly with Payments2Us so we can review your configuration and advise on the appropriate action.
Action Required: Disable (untick) the Lightning Features for Guest Users setting on the Salesforce Site hosting your Payments2Us forms.
Why is this change required?
This requirement follows a review of guest user configurations across our customer base. We identified that Lightning Features for Guest Users does not need to be enabled for Payments2Us forms to function correctly.
When this setting is enabled, additional lightning (Aura and Lightning Web Component) functionality becomes available to unauthenticated guest users on your site - functionality Payments2Us forms don't use. Leaving it enabled is unecessary:
- Widens the functionality available to unauthenticated visitors on your site
- Exposes more Lightning-based functionality to guest users than your implementation needs
- Works against the least-privilege approach Salesforce recommends for guest user configuration
Disabling it is a straightforward way to reduce that exposure, and it's consistent with Salesforce's own broader guidance on limiting guest user functionality to only what a site actually requires. The below article is from Salesforce on this very issue, and is date March 7th, 2026.
https://www.salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-access/
When to make this change
This setting should be reviewed and addressed in every Salesforce org where Payments2Us is installed, including production and Sandbox environments.
We recommend implementing the change in your production environment as soon as possible and also reviewing each Sandbox separately. Salesforce Site settings and configurations can differ between environments, so completing the change in production does not necessarily mean it has also been completed in your Sandboxes.
We do not anticipate any impact to standard Payments2Us payment forms as a result of this change. However, organisations with customisations should validate their payment forms by following Steps 5 and 6.
If your Payments2Us forms are hosted on a Salesforce Experience Cloud site, please log a support case directly with Payments2Us for guidan
How to Disable Lightning Features for Guest Users
Follow the steps below in Salesforce.
Step 1: Go to your setup, type ‘Sites’ in the Quick Find, and then click on ‘Sites’.

Step 2: Click the Salesforce Site that hosts your Payments2Us forms, often called “Payment” or “Payments.” If more than one Salesforce Site hosts Payments2Us forms, repeat Steps 2–6 for each site.

Step 3: Click ‘Edit’.

Step 4: Untick the Lightning features for guest users checkbox and click ‘Save’.

Step 5: Click on ‘Back to List: Sites’

Step 6: Scroll to your Payments2Us site (often called ‘Payments’) and click on Site URL. Check that it loads correctly without errors.

Frequently Asked Questions
Why do I need to disable the Lightning Features for Guest Users setting?
Disabling this setting is a mandatory security hardening measure. Leaving it enabled gives unauthenticated guest users more functionality than Payments2Us forms require, which widens what's exposed to a guest user.
Is this change mandatory?
Yes. All customers hosting Payments2Us forms using Salesforce Experience Cloud or Salesforce Sites should disable the Lightning Features for Guest Users.
What if we have more than one Payments2Us Site?
The setting must be reviewed separately on every Salesforce Site that hosts Payments2Us forms. Updating one site does not automatically update the setting on other sites within the same Salesforce org. Refer to Step 2 above.
Does this requirement also apply to Sandbox environments?
Yes. When this article refers to an “org,” it means every Salesforce org in which Payments2Us is installed, including your production org and all Sandbox environments.
The relevant configuration should be reviewed separately in each org because Salesforce Site and guest-user settings may differ between production and Sandbox environments.
What should I do if my Payments2Us forms are hosted on an Experience Cloud site?
If your Payments2Us forms are hosted on a public-facing Salesforce Experience Cloud site and can be accessed without requiring the user to log in, please log a support case directly with Payments2Us.
This means the form is available to unauthenticated visitors or Experience Cloud guest users. Experience Cloud implementations can differ from standard Salesforce Sites, so our team will review how your Payments2Us forms are hosted and advise you on the appropriate action for your configuration.
If the Payments2Us form is only available after an authenticated user has logged in, this specific guest-user guidance may not apply.
Will disabling this setting affect my users?
This setting only affects guest (unauthenticated) users.
We recommend implementing this change in your production environment as soon as possible. We do not anticipate any impact to standard payment forms as a result of this change. However, organisations that have applied customisations should validate their payment forms (By following step 5 and 6 within this article) after implementation to confirm they continue to operate as expected.
What should I do before making this change?
We recommend implementing this change in your production environment as soon as possible. We do not anticipate any impact to standard payment forms as a result of this change. However, organisations that have applied customisations should validate their payment forms (By following step 5 and 6 within this article) after implementation to confirm they continue to operate as expected.
What if my organisation requires this setting to remain enabled?
If you believe your implementation depends on this setting, please contact our support team before making any changes. We can discuss your configuration, discuss alternative approaches where appropriate, and help you implement the most secure solution. Please note this will require premium support, as we work with you to determine the best course of action for your custom components.
Who should I contact if I need assistance?
If you do not have a Salesforce Administrator or implementation partner, or if you require additional assistance with your Payments2Us configuration, please contact the Payments2Us Support Team. Please note this will require premium support, as we work with you to determine the best course of action for your custom components.